LemmaAnalysis
Login
Security · The less we hold, the less can go wrong

Your data, protected by restraint as much as encryption.

We encrypt what we hold and harden how we hold it — but the strongest safeguard is how little we ask for in the first place. No stored card numbers, no brokerage passwords, nothing sold to anyone.

EncryptedMinimalNot a brokerNot for sale

Security at a glance

Encrypted in transit

Every request travels over HTTPS/TLS. A strict Content-Security-Policy and hardened response headers guard the app in your browser.

Sessions you can’t leak

You’re kept signed in with an HTTP-only cookie — invisible to page scripts, so a cross-site script can’t read or steal it — and every write carries a CSRF header.

We never touch your money

Lemma Analysis executes no trades and moves no money. Connecting a broker is optional and read-only — a key you issue and can revoke at the broker — so there is nothing here that could place an order.

We store less of you

We keep your email and what you choose to enter — nothing more. No card numbers, no brokerage passwords, no data sold to advertisers.

How your data is stored and encrypted

Security is a chain of specific, boring engineering choices — not a slogan. Here is what actually protects your account and your research, from the browser to the database.

Encryption in transit

All traffic between your browser and our servers is encrypted with TLS (HTTPS). We add a Content-Security-Policy and modern security headers so the page itself resists tampering and script injection.

Session handling

Authentication uses an HTTP-only, same-site session cookie rather than a token in local storage. Because JavaScript cannot read it, a cross-site scripting bug cannot exfiltrate your session, and state-changing requests must carry an anti-CSRF header to be accepted.

What we actually store

Your account email, your password (only ever kept as a salted one-way hash — never in readable form), and the research data you create: portfolios you enter, watchlists, journal notes, and saved screens. If you connect a brokerage account, we also hold the read-only key you issued for it — encrypted, never returned in any response, never written to a log, and left out of your data export. That is the extent of it.

Payments stay with the processor

Subscriptions are handled by LemonSqueezy, our payment provider and merchant of record. Your card details are entered on their PCI-compliant checkout and never pass through — or get stored on — our servers.

How we keep your investing safe

The safest way to secure a trade is never to be able to place one. Lemma Analysis is a research terminal, not a broker — it helps you decide, then you act in your own brokerage account, entirely outside our reach.

We never connect to your bank, and a broker only if you ask — with a read-only key you issue there and can revoke there. Whether you enter holdings by hand, import a file or connect a broker, there is no way for us — or anyone who breached us — to move your money: a read-only key cannot place an order, and nothing here is built to try. It’s the same principle behind everything on this page: the capability we don’t have is the risk you don’t carry.

What we never do with your data

Some of the strongest guarantees are the ones about what does not happen.

We never sell or rent your data

Not to advertisers, not to data brokers, not to anyone. Our revenue is subscriptions alone, so there is no incentive to monetise you.

We never ask for your brokerage login

The platform doesn’t link to your bank, and it never asks for your broker password. If you connect a broker, you issue a read-only key yourself and can revoke it there at any moment; we store it encrypted, never show it again — not even to you — and delete it the moment you disconnect.

We never store your card number

Card data lives with our PCI-compliant payment processor, not with us. We see a plan and a status, not your card.

We never track you across the web

Product analytics are cookieless and aggregate. There are no third-party advertising trackers following you off our site.

Compliance and your privacy rights

GDPR by law, not by badge

The service is operated from the Czech Republic, which places it squarely under the EU’s GDPR. That is a legal obligation we already carry — the right to access, export, correct and delete your data — not a certificate we bought.

Data minimisation as design

The best way to comply with data-protection law is to collect little in the first place. We ask for what the product genuinely needs and nothing more, which shrinks both your exposure and our obligations.

Your rights, honoured

You can view the data tied to your account, export it, and delete your account and its data at any time. How we collect, use and retain data is spelled out in full on our Privacy page.

The full detail lives in our Privacy Policy and Terms, and our approach to independence and transparency is set out on the About page.

Audits and ongoing security

We’d rather be honest than impressive. Lemma Analysis does not yet hold formal third-party certifications such as SOC 2 or ISO 27001 — those are a goal we’re working toward, not a badge we’ll pretend to have. What we do today is run our own security reviews of the application and its dependencies, keep the attack surface deliberately small, and fix issues as we find them.

Security is never finished, so we treat it as ongoing work rather than a one-time box to tick. If you’re a researcher and you find a weakness, we want to hear about it: email support@lemma-analysis.com and give us a reasonable window to fix it before any public disclosure. Responsible reports are always welcome.

FAQ

Is my data safe with Lemma Analysis?

Your data is encrypted in transit with TLS, your session is held in an HTTP-only cookie that page scripts cannot read, and your password is stored only as a salted one-way hash. Just as importantly, we deliberately store very little: your email and the research you create. We never sell your data, and never store your card number. Connecting a brokerage account is optional and read-only: you issue the key, you can revoke it at the broker, and we keep it encrypted and never show it again.

Do you connect to my brokerage or bank account?

To a bank, never. To a broker, only if you ask us to, and only to read. Lemma Analysis is a research and analysis tool, not a broker: it executes no trades and cannot move your money. You can enter holdings by hand, import a file you exported, or connect a supported broker with a read-only key that you issue at the broker and can revoke there at any time. We never receive your brokerage login, and disconnecting deletes the key.

How are payments handled — do you store my card?

No. Subscriptions are processed by LemonSqueezy, a PCI-compliant payment provider and merchant of record. Your card details are entered on their secure checkout and never reach or get stored on our servers. We only ever see your plan and its status.

Are you GDPR compliant?

Yes. The service is operated from the Czech Republic and therefore falls under the EU’s GDPR. You have the right to access, export, correct and delete your personal data, and our Privacy page documents exactly what we collect and why.

Are you SOC 2 or ISO 27001 certified?

Not today, and we would rather tell you that plainly than imply otherwise. Formal third-party certifications are a roadmap item, not a current claim. What we can point to now is the architecture: encrypted transport, hardened sessions, a salted password store, brokerage access that is read-only and revocable by you, no stored card data, and a policy of collecting as little as possible.

How do I report a security issue?

We welcome responsible disclosure. If you believe you have found a vulnerability, email us at support@lemma-analysis.com with the details and we will investigate promptly. Please give us a reasonable window to fix an issue before disclosing it publicly.

Research with confidence.

Free to start. No credit card. Nothing sold, ever.